Toto-Rex . Global edition . totorex.ai/global Study Corner
Toto-Rex Toto-RexTMGlobal edition . AI compliance & governance
Menu
Subscribe
Global focus . comparison . treaties . industry . the agenda

How the world governs AI

"One planet. Sixty rulebooks. Zero excuses."

Fourteen jurisdictions, one satellite. Drag to spin; pick a node to open its dossier below.

There is no World AI Act and no global AI regulator. There is something more interesting: dozens of national frameworks, one treaty gathering ratifications, a soft-law layer everyone quotes, and an industry racing ahead of all of it. This edition puts them side by side: the frameworks, the organisations, the agenda, the money and the machines, in plain language.

Choose a language above. English is the controlling text and prevails over any translation. Traditional and Simplified Chinese, French, Spanish, Russian and Arabic cover the dossiers and their in-depth analyses, the essays and the data desks on this page. Japanese, Korean, Hindi, Portuguese, Welsh, Scottish Gaelic, Irish and Scots are machine translations, checked by automated tests. No translation on this site is certified.

14 jurisdiction dossiers 12 international bodies mapped 15 languages, including all six UN official languages 0 global AI regulators (really)

The global letter is coming soon.

Pick a folder; the desk shows only what you need. The side rail and menus still reach everything.

01
The global framework . how the world governs AI

Pick a region. See how it governs AI.

The rules in force, an honest read on where each place stands, and the documents that prove it.

AI here means software that learns patterns from data to produce outputs, predictions, text, images, recommendations, decisions, rather than following steps a person wrote by hand. It is governed because those outputs increasingly carry real stakes, over jobs, credit, health, safety and speech, and a system that learns can be opaque, biased or simply wrong in ways nobody intended. Every jurisdiction below is answering one question: how to keep the benefit while holding someone accountable for the harm.

Some places wrote one big statute. Some wrote a dozen small rules. Some wrote none and govern anyway. Choose a jurisdiction and you get the laws that actually bind there, Toto-Rex's plain-language summary of where it stands right now, and links to the primary documents and cases so you can check him. Fourteen dossiers, one map; none of it is legal advice.

Educational only, not legal advice. Each dossier links its primary sources; check the date shown before you rely on anything. Dossiers as at 11 July 2026; treaty status updated against the Council of Europe depositary record as at 13 July 2026. Regulatory position updated 22 September 2026: the EU dates reflect the Digital Omnibus on AI (in force 27 July 2026). That update covered the EU timeline; every other jurisdiction carries the date shown inside its own dossier. The Council of Europe treaty is still not in force: the European Union ratified on 15 May 2026 and remains the only party to have done so, of the five consents required.

02
Comparison . rationale . approach . timeline

Five ways to govern a machine

Every framework on Earth is one of five models. Usually a blend.

Strip away the acronyms and the world has settled on five governance models. Each has a rationale, a way of binding, and a timeline. The interesting part: no jurisdiction copied another exactly, and the differences are deliberate.

Condensed from the jurisdiction dossiers above and the research library's executive atlas (cut-off 13 July 2026). The full comparative essays live in the UK & EU and Asia editions.

03
Featured vocabulary . the words that run the world

Eight words that explain global AI law

Learn these and every headline in this edition reads itself.

From the full glossary: 350+ terms, with examples.

04
International organisations . instruments . status

The role of international bodies

Twelve bodies, one honest status label each.

A layered framework exists above national law: one treaty, several recommendations, political processes and technical standards. The label matters more than the logo. "International law requires" is almost never the right sentence; instrument, party, scope and domestic effect decide what actually binds.

Reading the labels: a treaty binds only states that ratify it, and only once in force. Binding regional law (like the EU AI Act) binds directly within its scope. Soft law (recommendations, principles) guides without binding. Voluntary standards bind only when a contract, regulator or law adopts them. Status recorded as at 13 July 2026 from the research library's register; sources linked on each card.

05
The agenda . intergovernmental events . timeline

The agenda, dated and labelled

What happened, what is scheduled, and what is only conditional.

Toto-Rex's watchlist

    Review cadence: quarterly, and after every UNGA, G7/G20 digital ministerial, OECD Council update, treaty deposit and major regional-law milestone. From the library's update protocol.

    Dates from the research library's global timeline (cut-off 13 July 2026). Future items are labelled; no forecast is a legal fact.

    06–08
    Toto-Rex's notes . working drafts

    Three essays from the global desk

    Longer reads. Pour a coffee.

    Essay no. 06 . international governance

    Why there is no global AI law, and why a treaty is still the best tool we have

    Toto-Rex . July 2026 . 6 min read . sources linked below

    Models cross borders. Training data crosses borders. Compute supply chains, synthetic content and the harms all cross borders. The laws do not. That mismatch is the central fact of AI governance in 2026, and it is worth understanding precisely why it persists.

    Why no universal regime exists

    1. Sovereignty. States genuinely disagree about privacy, speech, surveillance and the state's relationship with platforms. A single rulebook would have to pick winners among constitutions.
    2. Strategic competition. Compute, chips and models are treated as strategic assets. States hesitate to accept verification or constraints that might advantage rivals.
    3. Security carve-outs. Civilian rules can advance while military and intelligence uses stay contested or excluded.
    4. Moving definitions. A treaty negotiated around one architecture may age before it is ratified.
    5. Sector diversity. A clinical device, a hiring ranker and an industrial controller need different evidence and different regulators.
    6. Enforcement across borders. Developers, deployers, compute providers and users span jurisdictions; causal chains are complex.
    7. Capacity gaps. Many countries lack compute, testing labs or bargaining power, and reasonably resist rules written only by model-producing economies.
    8. Slow ratification. Even agreed treaties take years of signatures, ratifications and implementing law.

    Why a treaty is still the answer to inter-governmental conflict

    Consider the alternatives actually on offer. Unilateral extraterritorial law reaches across borders but breeds friction: duplicated audits, forum shopping and rules written by whichever market is largest. Soft law converges vocabulary but cannot bind a rival, compensate a victim or compel an investigation. Export controls manage a chokepoint but govern access, not behaviour, and the chokepoints move.

    Only a treaty creates reciprocal obligation between states that do not trust each other. That is what treaties are for. Verification, dispute settlement, mutual assistance and capacity funding cannot be improvised bilaterally at planetary scale; they need an instrument states have consented to. The research library's recommended architecture is deliberately modest: a thin binding floor for cross-border and severe risks (prohibited uses, incident reporting, contestability and remedy, whistle-blower protection, regulator access), a standards and mutual-recognition layer so evidence travels, national enforcement so constitutions keep their variation, shared science and incident learning built on the UN's new panel, and capacity and benefit-sharing so the regime is representative enough to be enforceable.

    The pieces exist. The Council of Europe Convention is the strongest current treaty template, open beyond Europe, with one of the five required consents filed so far, by the European Union on 15 May 2026. The UN Global Dialogue gives every state a seat, though it is explicitly non-negotiating. UNESCO provides the broadest ethical baseline; the OECD and G7 provide operational convergence; ISO/IEC provides the evidence format. None of this is a world regulator, and none of it should be oversold. It is a credible pathway, and pathways are how international law has always been built: slowly, then suddenly.

    Not legal advice; a plain-language essay for learning, drawing on the research library's global-governance analysis (cut-off 13 July 2026). The cited instruments are real; check their live status before relying on any of them.

    Essay no. 07 . security and strategy

    Why AI is the new national security

    Toto-Rex . July 2026 . 6 min read . neutral by design; key claims source-linked

    For seventy years, "strategic technology" meant things that explode, encrypt or fly. In 2026 the list has a new entry, and you can tell because governments are behaving exactly the way they always behave around strategic technology: counting it, restricting it, subsidising it and writing security exceptions into treaties about it.

    Four tells

    First, the counting. Compute is now measured like a strategic stockpile. South Korea's AI law triggers safety duties at a numeric compute threshold. Export rules define chips by performance density. Analysts publish national capacity in gigawatts and dies. When states start measuring something in official units, it has become strategic.

    Second, the restricting. Advanced chips are subject to United States export licensing, which shifted in January 2026 from a presumption of denial to conditional, case-by-case review, with ownership-based rules affirmed in June and preferential treatment extended to trusted partners in July. Access to compute is now a graduated, negotiated status between governments, which is precisely how strategic materials have always been handled.

    Third, the subsidising. The EU's InvestAI aims to mobilise 200 billion euros; sovereign wealth funds closed a 49-billion-dollar AI fund and a 20-billion-dollar infrastructure partnership within seven months; hyperscaler capital spending guided toward roughly 700 billion dollars for 2026, which cited analyses put close to the investment intensity of the dot-com peak as a share of GDP. States describe these programmes in the language of independence, not profit: the stated goal of most sovereign-AI plans is not to out-build anyone, but not to depend on anyone.

    Fourth, the carve-outs. The first international AI treaty contains national-security and defence exceptions. The UK renamed its evaluation body the AI Security Institute. The one domain where every governance framework goes quiet is the domain states consider most strategic. Silence, in treaty drafting, is a statement.

    What follows from it

    Three consequences matter for anyone doing compliance work. Supply chains become legal objects: where a chip may run, who may own the data centre and which subsidiaries count are now licensing questions, so provenance records and contract clauses about jurisdiction stop being boilerplate. Fragmentation becomes the default: a domestic-stack model trained wholly on one country's silicon and a sovereign cloud governed wholly by another's law are both rational responses to the same fear, and both are accelerating. And the civilian rulebooks inherit the tension: treaty carve-outs, filing regimes and evaluation institutes all draw the same line between what states regulate for citizens and what they reserve for themselves.

    None of this is presented here as good or bad. It is presented as weather: the conditions under which every AI compliance programme now operates. Toto-Rex's practical read is unchanged from the rest of this site: build to the strictest regime that reaches you, document your supply chain like it will be asked for, and treat "where may this model run" as a legal question, because several governments already do.

    Not legal or investment advice. Figures are as reported by the linked sources as at 14 July 2026; policies and numbers move quickly. Terms are kept deliberately neutral.

    Essay no. 08 . the state of the art

    Global AI compliance: the theory, the moment, and the way through

    Toto-Rex . July 2026 . 7 min read . draws on the book draft "AI Compliance Compared"; sources linked below

    The theory

    The lazy map of AI regulation is a dial from "strict" to "lax", with Brussels at one end and everyone else strung along it. The evidence does not support the dial. What the world actually produced is four philosophies of governing anything powerful and new: the comprehensive statute (the EU, now echoed by South Korea, Taiwan, Vietnam and Peru), the principled regulator (the UK, Singapore, Hong Kong, Japan), the adversarial patchwork (the United States, where states, agencies and courts write the real rules), and the plural market of answers (Asia taken whole, from China's one-rule-per-behaviour ladder to India's considered restraint). Each is a faithful expression of the legal culture that produced it, which is exactly why none of them copied another.

    Regimes drafted this differently still turn out to be commensurable, because they all answer the same six questions: what is the system's purpose, what data did it learn from, what decisions does it touch, what must be disclosed, who is accountable, and whose jurisdiction reaches it. That six-factor lens, developed in the book draft this essay leans on, is the working theory of this whole site: comparison is not about deciding who is right; it is the instrument that makes four right answers usable at once.

    The current situation

    As at September 2026 the scoreboard reads like this. One treaty exists and is not yet in force: the European Union ratified it on 15 May 2026 and remains the only party to have done so, while five consents, three of them from Council of Europe member states, are needed. That count is the single most watchable number in the field. One regional statute is binding and phasing in, with transparency duties in force since 2 August 2026. A statute club is quietly growing around it. The soft-law layer (OECD, UNESCO, G7) is broad, stable and increasingly operational, while the UN has built itself evidence machinery rather than a rulebook: a Scientific Panel and a Dialogue that is deliberately non-negotiating. Beneath all of it, data-protection law remains the enforcement muscle almost everywhere. And the industry has moved faster than every instrument named above: capital spending near historic records, frontier releases weeks apart, and compute treated by states as a strategic resource.

    The approaches, honestly compared

    Each philosophy pays its own price. The statute buys certainty and pays in weight; its 2026 simplification round proved even architecture bends. The principled regulator buys speed and pays in fragmentation; five principles across a dozen regulators means no single answer to "am I compliant?". The patchwork buys experimentation and pays in fifty answers where one was wanted. The market of answers buys fit and pays in translation costs for anyone crossing borders. Three gravities pull across all of them: Brussels through market size, Beijing through supply chains and filings, and the American states through sheer commercial reach. Distance from any of the three is not a defence.

    Looking forward

    The convergence that matters is not on instruments; it is on questions and evidence. Risk tiers, transparency labels, incident reporting and evaluation are appearing in every system under different names. The live questions for the next two years: whether the treaty crosses its ratification threshold; whether the UN Dialogue stays deliberative; whether incident reporting and model evaluation converge through the OECD, the G7 and the standards bodies, or fragment by bloc; and whether "sovereign AI" hardens from procurement language into law.

    Possible solutions

    For states, the credible path is the layered one this site keeps returning to: a thin binding floor for severe cross-border risks, interoperable evidence standards so one audit travels, national enforcement so constitutions keep their variation, shared science and incident learning, and capacity-sharing so the regime is representative enough to be enforceable. For everyone else, the solution already works today and does not wait for Geneva: read to the stricter rule. Build one system to the highest bar that reaches you, keep one proof file with jurisdiction annexes, appoint the local representatives, and treat every new instrument as a delta against the framework you already run, not a fresh headache. Four rulebooks, one floor, and the floor holds.

    Not legal advice. The four-philosophies framing, the six-factor lens, the "three gravities" and "read to the stricter rule" are drawn, with the author's permission, from the book draft AI Compliance Compared: An Introduction (EW, Maqutt Publishing, in preparation); legal positions are stated as at the library cut-off of 13 July 2026 and linked to primary sources. Verify live status before relying on anything here.

    09
    The industry tracker . chips . infrastructure . deals

    Who is building what, where

    Compute, contracts and capital, country by country.

    Reported figures, not audited facts. Entries summarise the linked reports as at 14 July 2026; corporate plans and government programmes change. Nothing here is investment advice.

    10
    Financial performance . as reported

    The world in numbers

    Eight figures that describe the AI economy right now.

    Reported and guided figures from the linked sources, as at 14 July 2026. Round numbers are rounded; currencies as reported. Not investment advice.

    11
    New technology . the frontier

    What the machines learned this year

    The 2026 model wave, in four honest observations.

    Model names and dates as reported by the linked trackers, as at 14 July 2026. Benchmark claims are the vendors' and testers' own; treat leaderboards as weather reports.

    12
    Restrictions . access . flows

    Compute diplomacy, described neutrally

    Who may buy what, and how the map is redrawn.

    Every state in this story is doing the same thing: securing its own access to a technology it considers strategic. The measures differ; the motive rhymes. These cards describe the measures as reported, without taking sides.

    As at 14 July 2026. Export rules change quickly and carry penalties; if they may apply to you, take specialist trade-law advice. This page is education, not clearance.

    13
    Global news desk . AI development

    The news that moves the map

    Curated, dated, and linked to the original outlet.

    Headlines link their original outlets; the one-line gists are Toto-Rex's own. Curated 14 July 2026. This page updates when Toto-Rex refreshes it, so check the date and the sources for the latest.

    14
    Go deeper . regional editions

    Overviews, region by region

    The deep dives live in the regional editions.

    How this edition is sourced

    Legal content (sections 01 to 07) is drawn from the English Toto-Rex AI Compliance Library, version 6.1.1: 187 research documents across twelve jurisdiction packs, an international-governance collection and a source register of 431 official URLs. Research cut-off: 13 July 2026. Automated checks are not legal or linguistic certification. Browse the English library.

    Industry content (sections 08 to 12) summarises the press, analyst and filing sources linked on each card, as at 14 July 2026. Reported figures are not audited; company plans change; nothing is investment advice.

    Updates: this page is updated with new research, and each section carries the date it was last updated. If a date looks stale, the sources linked on every card are the live truth. Not legal advice; the English version prevails.

    The global letter

    One world, one email, roughly monthly

    What moved in global AI governance and industry, in plain language, with key claims source-linked. No spam, no selling your address; unsubscribe any time.

    Sign-up opens soon.

    Toto-Rex can make mistakes. Everything here is general information, not legal advice: check the primary source, and take advice from a qualified professional before you act.